The Clock Doesn't Lie: Timing Attacks in Authentication Flows
A timing side-channel in JSONAuth allows unauthenticated attackers to enumerate valid usernames based on response time differences.
CATEGORY
Investigations into vulnerabilities, exploit paths, and root-cause behavior.
A timing side-channel in JSONAuth allows unauthenticated attackers to enumerate valid usernames based on response time differences.
Analysis of a password change flow that accepts a valid session token without requiring current-password reauthentication.
An analysis of an incomplete remediation in FileBrowser Quantum where tokenized download URLs remained exposed, resulting in an authentication bypass despite a prior security fix.
Investigation into an authentication bypass caused by trusting a forwarded identity header at the edge gateway.